Privacy questions, answered
Ask in your own words, or pick a question below. Nothing you type is stored, and your question never appears in the address bar.
Most asked
- Do I have to register with the ICO or pay the data-protection fee?
Probably yes — in the UK you pay the ICO fee; in Zimbabwe you need a POTRAZ licence by tier. Two minutes to find out.
- Do I need a privacy policy on my website?
If you collect any personal data, yes — and a copy-pasted template usually will not pass.
- We had a data breach — do I have to report it?
Maybe, and fast: 24 hours to POTRAZ in Zimbabwe (including a suspected breach), 72 hours to the ICO in the UK. Triage it now.
- Someone asked for all the data I hold on them — what do I do?
You must respond, free, within a month. Check your DSAR readiness.
- Do I need a Data Protection Officer?
UK: usually no. Zimbabwe: usually yes, certified, within 90 days. Check your obligation.
- Do I need a cookie banner?
Non-essential cookies need real opt-in — scan your site.
- Can I send marketing emails to people who haven't opted in?
Only with consent or a valid soft opt-in. Check before you send.
- How long can I keep customer data?
Only as long as you have a purpose — build a retention schedule.
- Can I use ChatGPT or AI tools with customer data?
Carefully — check your AI readiness and shadow-AI exposure.
- Do data-protection laws even apply to my little business?
Almost certainly — get your exposure score.
- Can I store customer data on US servers or use a US cloud?
It's a transfer and needs a safeguard — run a transfer check.
- Do I need a contract with my software suppliers?
Yes — every processor needs a DPA. Check your vendors.
- What are the fines if I get this wrong?
Zimbabwe: up to a level 11 fine and 7 years, but a DPO-appointment lapse is lower at level 7 and 2 years. We show the current cash value from the standard scale rather than a fixed number.
- Do I always need consent to collect personal data?
Often not consent — find your correct lawful basis.
- I'm building an app — what privacy work do I need before launch?
A full pre-launch privacy stack — run the app-builder checklist.
- Which POTRAZ tier am I, and how much is the licence?
Your data-subject count sets your tier — and your tier sets the licence fee, shown live from the current fee schedule.
Other checks that fit
- Do I need a POTRAZ licence to hold customer data?
- I'm not based in Zimbabwe or the UK but I have users there — do the rules apply?
- How much does compliance actually cost?
- Where do I even start?
- Can the same person be the DPO and the owner or founder?
- Does my DPO need a certificate or training in Zimbabwe?
- What has to go in a privacy notice?
- Do I have to tell people how I use data I got from somewhere else?
- Do I need consent for Google Analytics or tracking?
- What's my lawful basis — and which one do I pick?
- Can I rely on legitimate interests instead of consent?
- Can I email existing customers?
- Can I buy or rent a marketing list?
- Do I need consent for SMS or WhatsApp marketing?
- What actually counts as a data breach?
- How long do I have to report a breach — 72 hours or 24?
- Do I have to tell the customers whose data leaked?
- How long do I have to respond to a subject access request?
- Can I charge for a data request, or refuse it?
- Someone asked me to delete their data — do I have to?
- When do I have to delete old data?
- Do I need to write down everything I do with data?
- Can I send personal data outside Zimbabwe or the UK?
- Is my SaaS, CRM or email tool compliant?
- We share data with a partner — what do we need?
- Can I collect data about children, and do I need parental consent?
- What is special-category or sensitive data, and what's different?
- My staff are pasting data into AI tools — is that a problem?
- Do I need a DPIA, and how do I do one?
- What happens if the regulator gets a complaint about me?